Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @XenoKovah
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @XenoKovah
-
Xeno Kovah proslijedio/la je Tweet
I don't think FM work for such complex systems as Intel CSME. Starting from Intel-SA-00086 there were found many bugs in CSME firmware. I think in 2012 you were working just on CSME 11.x. Why those trivial buffer overflow bugs were not found?https://twitter.com/intoverflow/status/1220909635672002560 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
Untrusted Roots: exploiting vulnerabilities in Intel ACMs by
@flothrone https://www.offensivecon.org/speakers/2020/alexander-ermolov.html …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Can folks point me at the earliest examples of exploit-technique papers/presentations I could cite where type confusion vulnerabilities are described as "type confusion" rather than UAF for instance? I see the term gain popularity ~2010 so it'd probably be then or earlier
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
So when did @_embedi_ disappear? Their website/twitter account was still up when I last posted a timeline update in Oct. Sanctions officially killed them? (aka presumably just reorganizing under another name?)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
A new set of "Mac firmware security" pages are finally out, thanks to
@XenoKovah. Check it out, it's what me and my teammates at Apple had beet working on really damn hard for the last several years.https://support.apple.com/guide/security/uefi-firmware-overview-seced055bcf6/web …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
Now live!
The new Apple Security Bounty! Https://developer.apple.com/security-bounty/ …
The new Apple Platform Security guide, featuring Mac for the first time!
https://support.apple.com/guide/security/welcome/web …
(PDF version: https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/apple-platform-security-guide.pdf …)
My Black Hat 2019 talk: https://www.youtube.com/watch?v=3byNNUReyvE&t=52 …
Happy holidays!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
Our
#BHUSA talk recording "Breaking Through Another Side: Bypassing Firmware Security Boundaries from Embedded Controller" is up! https://youtu.be/g-1Y466rDaI EC issue we found has a bigger impact from what we expected in the beginning https://support.lenovo.com/us/en/product_security/len-27764 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
If you’ve got a security-sensitive codebase, you should be using -ftrivial-auto-init=pattern in Clang. In 2020, there’s no good reason for uninitialized variables to be exploitable.https://twitter.com/jfbastien/status/1205333762361290752 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
My
@PacSecjp slides on Insecure Boot are now available here:https://github.com/abarisani/abarisani.github.io/tree/master/research/secure_boot …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Xeno Kovah proslijedio/la je Tweet
My team has been working a lot with TPM hardware lately and found some pretty critical issues with the spec. Here's our 90-day disclosure of a vulnerability report we sent to
@TrustedComputin. "Verifying TPM Boot Events and Untrusted Metadata"https://github.com/google/go-attestation/blob/master/docs/event-log-disclosure.md …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
By the way.. ;) http://david.g3ns.de/voltpwn/paper.pdf …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Xeno Kovah proslijedio/la je Tweet
Embargo ends -
#PlunderVolt is public: https://plundervolt.com/ It allows to induce faults into computations in SGX, breaking crypto and corrupting memory. https://www.youtube.com/watch?v=In3B9L5Jyo4 … Great collaboration with Kit Murdock,@sublevado,@halfdoof,@jovanbulck, Frank Piessens!!Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Actually...Is anyone else aware of a graceful UEFI to OS VT-d handoff mechanism being implemented in production code? It just occurred to me that even though we only advertised 2 world-firsts for firmware protection, this could be a 3rd thing?
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
But yes, if a firmware with VT-d support doesn't know the OS is VT-d compatible (which it won't for everything other than macOS, because there's no speced out way to do this) it's necessarily to disable VT-d around ExitBootServices()
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I made a slide about this for Ivan's BH talk, but I forgot it got removed due to lack of time, so I suppose I should comment. When Mac UEFI added VT-d in 2017, we considered this and added graceful handoff between UEFI VT-d and macOS VT-d for the next release (10.12.4 IIRC)https://twitter.com/mjg59/status/1201668833984970752 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Moving from a monolithic ring 0, anyone-who-gets-in-wins memory space to the ring 0/ring 3 + virtual memory separation we depend on in all other contexts? Sure, why notpic.twitter.com/5hCAK7XrX8
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Enabling VT-d before there's even RAM available? It's what you gotta do ¯\_(ツ)_/¯pic.twitter.com/tYESLWc2Rh
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Or for the work
@NikolajSchlej and I did on bringing SecureBoot to the MacPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Check it out for more about the first-in-the-world work
@CoreyKal & Rafal Wojtczuk have done for UEFI DMA protection and UEFI sandboxing of PCIe Option ROMshttps://twitter.com/radian/status/1197990878540775424 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.